The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the specified capacity to encode HTTP responses, likely resulting in OutOfMemoryError being thrown, or even the JVM process exiting.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14031 | Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit |
Github GHSA |
GHSA-889j-63jv-qhr8 | Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit |
Thu, 31 Jul 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse
Eclipse jetty |
|
| CPEs | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eclipse
Eclipse jetty |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 02 Jul 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat ocp Tools
|
|
| CPEs | cpe:/a:redhat:ocp_tools:4.12::el8 cpe:/a:redhat:ocp_tools:4.13::el8 cpe:/a:redhat:ocp_tools:4.14::el8 cpe:/a:redhat:ocp_tools:4.15::el8 cpe:/a:redhat:ocp_tools:4.16::el9 cpe:/a:redhat:ocp_tools:4.17::el9 cpe:/a:redhat:ocp_tools:4.18::el9 |
|
| Vendors & Products |
Redhat ocp Tools
|
Fri, 16 May 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat apache Camel Spring Boot |
|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:4.10.3 | |
| Vendors & Products |
Redhat
Redhat apache Camel Spring Boot |
Sat, 10 May 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 08 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the specified capacity to encode HTTP responses, likely resulting in OutOfMemoryError being thrown, or even the JVM process exiting. | |
| Title | Eclipse Jetty HTTP clients can increase memory allocation | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2025-05-08T18:31:44.196Z
Reserved: 2025-03-04T13:55:56.722Z
Link: CVE-2025-1948
Updated: 2025-05-08T18:31:35.426Z
Status : Analyzed
Published: 2025-05-08T18:15:41.990
Modified: 2025-07-31T16:28:26.603
Link: CVE-2025-1948
OpenCVE Enrichment
No data.
EUVD
Github GHSA